Skip to content

CI: Adopt the self-repository reference syntax - #67

Merged
ModeSevenIndustrialSolutions merged 1 commit into
lfreleng-actions:mainfrom
modeseven-lfreleng-actions:ci/self-repository-syntax
Sep 16, 2026
Merged

ModeSevenIndustrialSolutions merged 1 commit into
lfreleng-actions:mainfrom
modeseven-lfreleng-actions:ci/self-repository-syntax

Conversation

@ModeSevenIndustrialSolutions

@ModeSevenIndustrialSolutions ModeSevenIndustrialSolutions commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Why now

The pre-commit autoupdate pull request (#55) is blocked, and this is what
blocks it. That update lifts zizmor-pre-commit to v1.30.1, whose new
self-repository audit reports every ./ call:

zizmor ... Failed (exit code 12)
help[self-repository]: use GitHub's dedicated self-repository syntax
      uses: ./.github/workflows/...
            ^^^ use '$/...' instead of './...'

What changed

Converted 1 call site in testing.yaml to the self-repository form.

A uses: value beginning $/ resolves to the workflow's own repository at
the commit already running
, with no checkout. GitHub added it in July 2026
and now recommends it for sibling workflows.

./ and $/ resolve identically here. For a reusable workflow call GitHub takes the called workflow from the caller's commit either way, so neither depends on checkout state and neither can go stale. What changes is the spelling GitHub documents as correct: $/ is now the recommended form for a workflow in the same repository.

The stronger guarantee people attach to $/ belongs to actions, not workflows. A step's uses: ./path really is workspace-relative and needs a checkout first; the job-level uses: converted here never was. The two spellings look alike and the distinction is easy to get backwards, so it is written down rather than left to inference.

One caveat travels with the form: $/ does not exist on GitHub Enterprise Server. Nothing here is affected, because the reference is internal to a workflow that only ever runs in this repository, but anyone copying the pattern into GHES still needs ./.

actionlint still rejects the form

So .github/actionlint.yaml gains a path-scoped ignore, placed as a new entry for the affected file(s).
The pattern matches only a value beginning $/:

- 'reusable workflow call "\$/.+" at "uses" is not following the format'

Anything else malformed at uses: still fails, so this buys compatibility
with the new syntax rather than switching the check off. The comment carries
the condition for removing it.

Verification

Checked against the zizmor version the autoupdate introduces, before and
after the change:

self-repository findings   before=2   after=0

Both pinned pre-commit hooks pass on the result:

actionlint ... Passed
zizmor ...... Passed

Also run: prek run --all-files (all hooks, no files modified) and
aislop ci --changes (0 errors, 0 warnings).

Once this merges, #55 should go green on a rebase or a re-run.

@ModeSevenIndustrialSolutions
ModeSevenIndustrialSolutions requested review from a team and a balanced review from Copilot September 16, 2026 16:58
@github-actions github-actions Bot added the CI CI and tests updates label Sep 16, 2026

This comment was marked as outdated.

This comment was marked as outdated.

This comment was marked as outdated.

GitHub added a self-repository reference in July 2026: a 'uses:' value
beginning '$/' resolves to the workflow's own repository at the commit
already running, with no checkout, and is now the recommended way to
call a sibling workflow.

Behaviour does not change. For a reusable workflow call GitHub
resolves both './' and '$/' from the caller's commit, so neither
depends on checkout state and neither can go stale. What changes is
the spelling GitHub documents as correct: '$/' is the form it now
recommends for a workflow in the same repository.

The stronger guarantee people attach to '$/' belongs to actions, not
workflows. A step's 'uses: ./path' really is workspace-relative and
needs a checkout first; the job-level 'uses:' converted here never
was. The two spellings look alike and the distinction is easy to get
backwards, so it is recorded here rather than left to inference.

One caveat travels with the form: '$/' does not exist on GitHub
Enterprise Server. Nothing here is affected, because the reference is
internal to a workflow that only ever runs in this repository, but
anyone copying the pattern into GHES still needs './'.

zizmor asks for the change directly. Its self-repository audit, added
in v1.30, reports every './' call and offers an auto-fix, so the
pre-commit autoupdate that lifted the hook past that version turned
the check red and blocked that pull request.

actionlint has not caught up and rejects the form as malformed, so
.github/actionlint.yaml gains path-scoped ignores. Each one names the
workflow it excuses rather than matching '$/' generally: a wildcard
would also swallow the diagnostic for a mistyped sibling path, which
is the one thing the check can still catch while the form is unknown
to it. Confirmed by pointing a call at a path that does not exist and
watching actionlint report it. A call added or renamed needs its own
line, and they all go once actionlint learns the form.

The file header moves with it. It described the workflows as
referenced by local path, which was the mechanism rather than the
intent, and leaving it would have told the next reader that checkout
state decides which workflows run.

The prose follows the call sites. .github/actionlint.yaml still
carried the template's note that no ignore rules were required, which
the block below it now contradicts, and README.md still described the
self-test as calling the skeleton by local path. Both named the
mechanism this change replaces, so leaving them would have handed the
next reader the old one.

Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Matthew Watkins <mwatkins@linuxfoundation.org>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The syntax, documentation, and narrowly scoped lint exception are consistent and complete.

Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

@zxiiro zxiiro left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Auto-approved by agent: reviewed workflow/code change for security and CI/CD impact, found low risk. Switches same-repo reusable workflow calls from ./ to GitHub $/ self-repository form (resolves identically at the running commit); narrow path-scoped actionlint ignores only; no permissions/secrets/trigger changes. CI green.

@ModeSevenIndustrialSolutions
ModeSevenIndustrialSolutions merged commit 731bfd4 into lfreleng-actions:main Sep 16, 2026
26 checks passed
@ModeSevenIndustrialSolutions
ModeSevenIndustrialSolutions deleted the ci/self-repository-syntax branch September 16, 2026 22:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI CI and tests updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants